Back to skill

Security audit

md2pdf-xelatex

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Markdown-to-PDF converter, but it compiles user-controlled Markdown through XeLaTeX without disabling raw TeX or adding sandbox limits, so untrusted documents need review before use.

Install only if you plan to convert Markdown you created or otherwise trust. Avoid running this skill on downloaded or user-submitted Markdown unless you isolate it in a container or sandbox, because raw LaTeX in the document may be interpreted by XeLaTeX under your local user permissions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/md2pdf.sh:78
Finding

Untrusted Markdown Is Compiled with Raw LaTeX Enabled

Content
View full analysis
/g' \ > "$TMPDIR/input.md" ``` ```bash # --- Build pandoc command --- PANDOC_ARGS=( "$TMPDIR/input.md" -o "$OUTPUT" --pdf-engine=xelatex -f markdown-smart -H "$HEADER_FILE" -V "mainfont=$MAIN_FONT" -V "sansfont=$MAIN_FONT" -V "monofont=$MONO_FONT" -V "geometry:margin=$MARGIN" -V "fontsize=$FONT_SIZE" -V colorlinks=true -V linkcolor=blue -V urlcolor=blue --highlight-style="$HIGHLIGHT" ) if [ -n "$TOC" ]; then PANDOC_ARGS+=($TOC -V "toc-title=$TOC_TITLE") fi # --- Run pandoc --- echo "Converting: $INPUT -> $OUTPUT" >&2 echo " Engine: xelatex | Font: $MAIN_FONT | Mono: $MONO_FONT | Size: $FONT_SIZE | Margin: $MARGIN" >&2 pandoc "${PANDOC_ARGS[@]}" 2>&1 | while IFS= read -r line; do ``` ### Technical Analysis The script accepts a caller-supplied Markdown file and processes it with Pandoc's `markdown` reader before compiling the resulting document through XeLaTeX. The selected input format, `markdown-smart`, does not disable Pandoc's raw TeX extension. Raw LaTeX embedded in the source Markdown can therefore be preserved and evaluated by XeLaTeX. The sanitization stage only replaces a fixed set of emoji, smart quotes, and punctuation. It does not remove or validate raw TeX commands. An attacker who can influence the input document can consequently inject TeX primitives or package commands into the compilation process. Depending on the host's TeX security configuration, injected TeX may attempt to read files accessible ...[truncated 2160 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/md2pdf.sh (reported line 31)May include surrounding context.

sh
# --- Check prerequisites ---
for cmd in pandoc xelatex; do
  if ! command -v "$cmd" &>/dev/null; then
    echo "ERROR: '$cmd' not found. Install: sudo apt install pandoc texlive-xetex texlive-fonts-recommended texlive-fonts-extra texlive-latex-extra texlive-lang-chinese" >&2
    exit 1
  fi
done

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script hard-codes the TOC title to "目录", which forces a specific language choice in generated output regardless of the user's locale or preferences. This is a natural-language policy concern because the file does not offer a language selection mechanism or explain that the tool is intentionally Chinese-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.